peter bassill · operator
$ cve CVE-2023-41892 JSON

CVE-2023-41892

10.0
CRITICAL · CVSS 3.1 · EPSS 94.2% (pctl 100)

Patch early

EPSS 94.2% — above the 10% action threshold.

Description

Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
EPSS94.22% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploitnone known
Published2023-09-13
Last modified2026-06-17

Affected (1)

VendorProduct
craftcmscraft cms

References

→ the Explorer  ·  watch your stack  ·  NVD